-
-
Notifications
You must be signed in to change notification settings - Fork 108
/
Copy pathdsiprouter.sh
executable file
·4992 lines (4498 loc) · 204 KB
/
dsiprouter.sh
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
97
98
99
100
101
102
103
104
105
106
107
108
109
110
111
112
113
114
115
116
117
118
119
120
121
122
123
124
125
126
127
128
129
130
131
132
133
134
135
136
137
138
139
140
141
142
143
144
145
146
147
148
149
150
151
152
153
154
155
156
157
158
159
160
161
162
163
164
165
166
167
168
169
170
171
172
173
174
175
176
177
178
179
180
181
182
183
184
185
186
187
188
189
190
191
192
193
194
195
196
197
198
199
200
201
202
203
204
205
206
207
208
209
210
211
212
213
214
215
216
217
218
219
220
221
222
223
224
225
226
227
228
229
230
231
232
233
234
235
236
237
238
239
240
241
242
243
244
245
246
247
248
249
250
251
252
253
254
255
256
257
258
259
260
261
262
263
264
265
266
267
268
269
270
271
272
273
274
275
276
277
278
279
280
281
282
283
284
285
286
287
288
289
290
291
292
293
294
295
296
297
298
299
300
301
302
303
304
305
306
307
308
309
310
311
312
313
314
315
316
317
318
319
320
321
322
323
324
325
326
327
328
329
330
331
332
333
334
335
336
337
338
339
340
341
342
343
344
345
346
347
348
349
350
351
352
353
354
355
356
357
358
359
360
361
362
363
364
365
366
367
368
369
370
371
372
373
374
375
376
377
378
379
380
381
382
383
384
385
386
387
388
389
390
391
392
393
394
395
396
397
398
399
400
401
402
403
404
405
406
407
408
409
410
411
412
413
414
415
416
417
418
419
420
421
422
423
424
425
426
427
428
429
430
431
432
433
434
435
436
437
438
439
440
441
442
443
444
445
446
447
448
449
450
451
452
453
454
455
456
457
458
459
460
461
462
463
464
465
466
467
468
469
470
471
472
473
474
475
476
477
478
479
480
481
482
483
484
485
486
487
488
489
490
491
492
493
494
495
496
497
498
499
500
501
502
503
504
505
506
507
508
509
510
511
512
513
514
515
516
517
518
519
520
521
522
523
524
525
526
527
528
529
530
531
532
533
534
535
536
537
538
539
540
541
542
543
544
545
546
547
548
549
550
551
552
553
554
555
556
557
558
559
560
561
562
563
564
565
566
567
568
569
570
571
572
573
574
575
576
577
578
579
580
581
582
583
584
585
586
587
588
589
590
591
592
593
594
595
596
597
598
599
600
601
602
603
604
605
606
607
608
609
610
611
612
613
614
615
616
617
618
619
620
621
622
623
624
625
626
627
628
629
630
631
632
633
634
635
636
637
638
639
640
641
642
643
644
645
646
647
648
649
650
651
652
653
654
655
656
657
658
659
660
661
662
663
664
665
666
667
668
669
670
671
672
673
674
675
676
677
678
679
680
681
682
683
684
685
686
687
688
689
690
691
692
693
694
695
696
697
698
699
700
701
702
703
704
705
706
707
708
709
710
711
712
713
714
715
716
717
718
719
720
721
722
723
724
725
726
727
728
729
730
731
732
733
734
735
736
737
738
739
740
741
742
743
744
745
746
747
748
749
750
751
752
753
754
755
756
757
758
759
760
761
762
763
764
765
766
767
768
769
770
771
772
773
774
775
776
777
778
779
780
781
782
783
784
785
786
787
788
789
790
791
792
793
794
795
796
797
798
799
800
801
802
803
804
805
806
807
808
809
810
811
812
813
814
815
816
817
818
819
820
821
822
823
824
825
826
827
828
829
830
831
832
833
834
835
836
837
838
839
840
841
842
843
844
845
846
847
848
849
850
851
852
853
854
855
856
857
858
859
860
861
862
863
864
865
866
867
868
869
870
871
872
873
874
875
876
877
878
879
880
881
882
883
884
885
886
887
888
889
890
891
892
893
894
895
896
897
898
899
900
901
902
903
904
905
906
907
908
909
910
911
912
913
914
915
916
917
918
919
920
921
922
923
924
925
926
927
928
929
930
931
932
933
934
935
936
937
938
939
940
941
942
943
944
945
946
947
948
949
950
951
952
953
954
955
956
957
958
959
960
961
962
963
964
965
966
967
968
969
970
971
972
973
974
975
976
977
978
979
980
981
982
983
984
985
986
987
988
989
990
991
992
993
994
995
996
997
998
999
1000
#!/usr/bin/env bash
#
#=============== dSIPRouter Management Script ==============#
#
# install, configure, and manage dsiprouter
#
#========================== NOTES ==========================#
#
# Supported OS:
# - Debian 12 (bullseye) - STABLE
# - Debian 11 (bullseye) - STABLE
# - Debian 10 (buster) - STABLE
# - Debian 9 (stretch) - DEPRECATED
# - CentOS 9 (stream) - STABLE
# - CentOS 8 (stream) - STABLE
# - CentOS 7 - STABLE
# - RedHat Linux 8 - ALPHA
# - Alma Linux 8 - ALPHA
# - Rocky Linux 8 - ALPHA
# - Amazon Linux 2 - STABLE
# - Ubuntu 22.04 (jammy) - ALPHA
# - Ubuntu 20.04 (focal) - DEPRECATED
#
# Conventions:
# - In general exported variables & functions are used in externally called scripts / programs
#
# TODO:
# - allow user to move carriers freely between carrier groups
# - allow a carrier to be in more than one carrier group
# - add ncurses selection menu for enabling / disabling modules
# - naming convention for system vs dsip config files is very confusing (make more explicit)
# - cleanup dependency installs/checks, many of these could be condensed
# - allow overwriting caller id per gwgroup / gw (setup in gui & kamcfg)
# - update tests with new mysql command wrapper functions
# - update HA scripts with new mysql command wrapper functions
# - add documentation generation to supported CLI commands
# - move python install into it's own script to allow fine grain control of version/compilation if needed
#
#============== Detailed Debugging Information =============#
# - splits stdout, stderr, and trace streams into 3 files
# - output files are timestamped throughout process (cpu intensive)
# - useful for tracking down bugs, especially when a lot of output is produced
# - the gawk version seems to be more efficient but mawk is supported as well
#
#mkdir -p /tmp/debug && rm -f /tmp/debug/*.log 2>/dev/null
#
# - gawk version (alias awk='gawk')
#exec > >(awk '{ print strftime("[%Y-%m-%d_%H:%M:%S] "), $0; fflush(); }' | tee -ia /tmp/debug/stdout.log)
#exec 2> >(awk '{ print strftime("[%Y-%m-%d_%H:%M:%S] "), $0; fflush(); }' | tee -ia /tmp/debug/stderr.log 1>&2)
#exec 19> >(awk '{ print strftime("[%Y-%m-%d_%H:%M:%S] "), $0; fflush(); }' > /tmp/debug/trace.log)
# - mawk version (alias awk='mawk')
#exec > >(awk -v time=$(date +"[%Y-%m-%d_%H:%M:%S] ") '{ print time, $0; fflush(); }' | tee -ia /tmp/debug/stdout.log)
#exec 2> >(awk -v time=$(date +"[%Y-%m-%d_%H:%M:%S] ") '{ print time, $0; fflush(); }' | tee -ia /tmp/debug/stderr.log 1>&2)
#exec 19> >(awk -v time=$(date +"[%Y-%m-%d_%H:%M:%S] ") '{ print time, $0; fflush(); }' > /tmp/debug/trace.log)
#
#BASH_XTRACEFD="19"
#set -x
#===========================================================#
# set project dir (where src files are located)
export DSIP_PROJECT_DIR=${DSIP_PROJECT_DIR:-$(dirname $(readlink -f "$0"))}
# Import dsip_lib utility / shared functions
. ${DSIP_PROJECT_DIR}/dsiprouter/dsip_lib.sh
# settings used by script that are user configurable
function setStaticScriptSettings() {
# to be clear, we define constants or variables with defaults here
# generally these configuration settings effect how this script or the platform operate
# do not change these settings without knowing exactly how it effects normal operation
FLT_CARRIER=8
FLT_PBX=9
FLT_MSTEAMS=17
FLT_OUTBOUND=8000
FLT_INBOUND=9000
FLT_LCR_MIN=10000
FLT_FWD_MIN=20000
WITH_LCR=1
export DEBUG=0
export TEAMS_ENABLED=1
DSIP_MIN_PYTHON_VER='3.8'
export PYTHON_VENV="${DSIP_PROJECT_DIR}/venv"
export PYTHON_CMD="${PYTHON_VENV}/bin/python"
export PROJECT_KAMAILIO_CONFIG_DIR="${DSIP_PROJECT_DIR}/kamailio/configs"
export PROJECT_DSIP_DEFAULTS_DIR="${DSIP_PROJECT_DIR}/kamailio/defaults"
export DSIP_SYSTEM_CONFIG_DIR="/etc/dsiprouter"
DSIP_PRIV_KEY="${DSIP_SYSTEM_CONFIG_DIR}/privkey"
export DSIP_KAMAILIO_CONFIG_FILE="${DSIP_SYSTEM_CONFIG_DIR}/kamailio/kamailio.cfg"
export DSIP_KAMAILIO_TLS_CONFIG_FILE="${DSIP_SYSTEM_CONFIG_DIR}/kamailio/tls.cfg"
export DSIP_CONFIG_FILE="${DSIP_SYSTEM_CONFIG_DIR}/gui/settings.py"
export DSIP_RUN_DIR="/run/dsiprouter"
export DSIP_LIB_DIR="/var/lib/dsiprouter"
export DSIP_CERTS_DIR="${DSIP_SYSTEM_CONFIG_DIR}/certs"
DSIP_DOCS_DIR="${DSIP_PROJECT_DIR}/docs/build/html"
export SYSTEM_KAMAILIO_CONFIG_DIR="/etc/kamailio"
export SYSTEM_KAMAILIO_CONFIG_FILE="${SYSTEM_KAMAILIO_CONFIG_DIR}/kamailio.cfg" # will be symlinked
export SYSTEM_KAMAILIO_TLS_CONFIG_FILE="${SYSTEM_KAMAILIO_CONFIG_DIR}/tls.cfg" # will be symlinked
export SYSTEM_RTPENGINE_CONFIG_DIR="/etc/rtpengine"
export SYSTEM_RTPENGINE_CONFIG_FILE="${SYSTEM_RTPENGINE_CONFIG_DIR}/rtpengine.conf"
export PATH_UPDATE_FILE="/etc/profile.d/dsip_paths.sh" # updates paths required
GIT_UPDATE_FILE="/etc/profile.d/dsip_git.sh" # extends git command
DSIP_SUDOERS_FILE="/etc/sudoers.d/99-dsiprouter"
export SRC_DIR="/usr/local/src"
export BACKUPS_DIR="/var/backups/dsiprouter"
IMAGE_BUILD=${IMAGE_BUILD:-0}
APT_OFFICIAL_SOURCES="/etc/apt/sources.list"
APT_OFFICIAL_PREFS="/etc/apt/preferences"
APT_OFFICIAL_SOURCES_BAK="${BACKUPS_DIR}/original-sources.list"
APT_OFFICIAL_PREFS_BAK="${BACKUPS_DIR}/original-sources.pref"
APT_DSIP_CONFIG="/etc/apt/apt.conf.d/99dsiprouter"
YUM_OFFICIAL_REPOS="/etc/yum.repos.d/official-releases.repo"
# Force the installation of an Kamailio version by uncommenting
# can also be set as an environment variable
#KAM_VERSION=57 # Version 5.7.x
# Force the installation of an RTPEngine version by uncommenting
# can also be set as an environment variable
#RTPENGINE_VER="mr11.5.1.11"
# Network configuration values
export DSIP_UNIX_SOCK='/run/dsiprouter/dsiprouter.sock'
export DSIP_PORT=5000
export RTP_PORT_MIN=10000
export RTP_PORT_MAX=20000
export KAM_SIP_PORT=5060
export KAM_SIPS_PORT=5061
export KAM_DMQ_PORT=5090
export KAM_WSS_PORT=4443
export HOMER_HEP_PORT=9060
export DSIP_PROTO='https'
export DSIP_API_PROTO='https'
export DSIP_SSL_KEY="${DSIP_CERTS_DIR}/dsiprouter-key.pem"
export DSIP_SSL_CERT="${DSIP_CERTS_DIR}/dsiprouter-cert.pem"
export DSIP_SSL_CA="${DSIP_CERTS_DIR}/ca-list.pem"
# make sure we run package installs unattended
if cmdExists 'apt-get'; then
export DEBIAN_FRONTEND="noninteractive"
export DEBIAN_PRIORITY="critical"
fi
# make perl CPAN installs non interactive
export PERL_MM_USE_DEFAULT=1
}
# settings used by script that are generated by the script
function setDynamicScriptSettings() {
# TEMP: parse these options ahead of time until we can move arg parsing ahead of this logic
# [note to self] this will require preempting undefined functions and/or some porting to bash-native versions of parsing logic
if [[ "$1" == "install" ]]; then
shift
local OPT
for OPT in "$@"; do
case $OPT in
-dmz|--dmz=*)
NETWORK_MODE=2
if echo "$1" | grep -q '=' 2>/dev/null; then
TMP=$(echo "$1" | cut -d '=' -f 2)
shift
else
shift
TMP="$1"
shift
fi
PUBLIC_IFACE=$(echo "$TMP" | cut -d ',' -f 1)
PRIVATE_IFACE=$(echo "$TMP" | cut -d ',' -f 2)
;;
-netm|--network-mode=*)
if echo "$1" | grep -q '=' 2>/dev/null; then
NETWORK_MODE=$(echo "$1" | cut -d '=' -f 2)
shift
else
shift
NETWORK_MODE="$1"
shift
fi
;;
esac
done
fi
# network settings determined by mode
NETWORK_MODE=${NETWORK_MODE:-$(getConfigAttrib 'NETWORK_MODE' ${DSIP_CONFIG_FILE})}
NETWORK_MODE=${NETWORK_MODE:-0}
# TODO: ipv6 intentionally disabled here
export IPV6_ENABLED=0
# grab the network settings dynamically
if (( $NETWORK_MODE == 0 )); then
export INTERNAL_IP_ADDR=$(getInternalIP -4)
export INTERNAL_IP_NET=$(getInternalCIDR -4)
export INTERNAL_IP6_ADDR=$(getInternalIP -6)
export INTERNAL_IP_NET6=$(getInternalCIDR -6)
# if external ip address is not found then this box is on an internal subnet
EXTERNAL_IP_ADDR=$(getExternalIP -4)
export EXTERNAL_IP_ADDR=${EXTERNAL_IP_ADDR:-$INTERNAL_IP_ADDR}
EXTERNAL_IP6_ADDR=$(getExternalIP -6)
export EXTERNAL_IP6_ADDR=${EXTERNAL_IP6_ADDR:-$INTERNAL_IP6_ADDR}
# determine whether ipv6 is enabled
# /proc/net/if_inet6 tells us if the kernel has ipv6 enabled
# if [[ -f /proc/net/if_inet6 ]] && [[ -n "$INTERNAL_IP6_ADDR" ]]; then
# # sanity check, is the ipv6 address routable?
# # if not we can not use this address (interface is not configured properly)
# if ! checkConn "$INTERNAL_IP6_ADDR"; then
# printerr "IPV6 enabled but address [$INTERNAL_IP6_ADDR] is not routable"
# exit 1
# fi
# export IPV6_ENABLED=1
# else
# export IPV6_ENABLED=0
# fi
# the address we put in the contact when registering to carriers via uac module
# by default it is set to the external IP of this server
export UAC_REG_ADDR="$EXTERNAL_IP_ADDR"
export INTERNAL_FQDN=$(getInternalFQDN)
export EXTERNAL_FQDN=$(getExternalFQDN)
if [[ -z "$EXTERNAL_FQDN" ]] || ! checkConn "$EXTERNAL_FQDN"; then
# if external fqdn is not routable set it to the internal fqdn instead
export EXTERNAL_FQDN="$INTERNAL_FQDN"
fi
# set the external fqdn to the internal fqdn if the hostname contain vultrusercontent
# Kamailio doesn't like hostname names with dots and LetsEncrypt can't create certs for that domain
grep vultrusercontent <<< "$EXTERNAL_FQDN" >/dev/null
if (( $? == 0 ));then
export EXTERNAL_FQDN="$INTERNAL_FQDN"
fi
# network settings pulled from env variables or from config file
elif (( $NETWORK_MODE == 1 )); then
export INTERNAL_IP_ADDR=${INTERNAL_IP_ADDR:-$(getConfigAttrib 'INTERNAL_IP_ADDR' ${DSIP_CONFIG_FILE})}
export INTERNAL_IP_NET=${INTERNAL_IP_NET:-$(getConfigAttrib 'INTERNAL_IP_NET' ${DSIP_CONFIG_FILE})}
export INTERNAL_IP6_ADDR=${INTERNAL_IP6_ADDR:-$(getConfigAttrib 'INTERNAL_IP6_ADDR' ${DSIP_CONFIG_FILE})}
export INTERNAL_IP_NET6=${INTERNAL_IP_NET6:-$(getConfigAttrib 'INTERNAL_IP_NET6' ${DSIP_CONFIG_FILE})}
export EXTERNAL_IP_ADDR=${EXTERNAL_IP_ADDR:-$(getConfigAttrib 'EXTERNAL_IP_ADDR' ${DSIP_CONFIG_FILE})}
export EXTERNAL_IP6_ADDR=${EXTERNAL_IP6_ADDR:-$(getConfigAttrib 'EXTERNAL_IP6_ADDR' ${DSIP_CONFIG_FILE})}
# if [[ -n "$IPV6_ENABLED" ]]; then
# export IPV6_ENABLED
# else
# [[ "$(getConfigAttrib 'IPV6_ENABLED' ${DSIP_CONFIG_FILE})" == "True" ]] &&
# export IPV6_ENABLED=1 ||
# export IPV6_ENABLED=0
# fi
export INTERNAL_FQDN=${INTERNAL_FQDN:-$(getConfigAttrib 'INTERNAL_FQDN' ${DSIP_CONFIG_FILE})}
export EXTERNAL_FQDN=${EXTERNAL_FQDN:-$(getConfigAttrib 'EXTERNAL_FQDN' ${DSIP_CONFIG_FILE})}
export UAC_REG_ADDR=${UAC_REG_ADDR:-$(getConfigAttrib 'UAC_REG_ADDR' ${DSIP_CONFIG_FILE})}
# network settings resolved dynamically except IP/subnets (they are resolved by interfaces from CLI args or from the config)
elif (( $NETWORK_MODE == 2 )); then
PUBLIC_IFACE=${PUBLIC_IFACE:-$(getConfigAttrib 'PUBLIC_IFACE' ${DSIP_CONFIG_FILE})}
PRIVATE_IFACE=${PRIVATE_IFACE:-$(getConfigAttrib 'PRIVATE_IFACE' ${DSIP_CONFIG_FILE})}
export INTERNAL_IP_ADDR=$(getIP -4 "$PRIVATE_IFACE")
export INTERNAL_IP_NET=$(getInternalCIDR -4 "$PRIVATE_IFACE")
export INTERNAL_IP6_ADDR=$(getIP -6 "$PRIVATE_IFACE")
export INTERNAL_IP_NET6=$(getInternalCIDR -6 "$PRIVATE_IFACE")
EXTERNAL_IP_ADDR=$(getIP -4 "$PUBLIC_IFACE")
export EXTERNAL_IP_ADDR=${EXTERNAL_IP_ADDR:-$INTERNAL_IP_ADDR}
EXTERNAL_IP6_ADDR=$(getIP -6 "$PUBLIC_IFACE")
export EXTERNAL_IP6_ADDR=${EXTERNAL_IP6_ADDR:-$INTERNAL_IP6_ADDR}
# if [[ -f /proc/net/if_inet6 ]] && [[ -n "$INTERNAL_IP6_ADDR" ]]; then
# # sanity check, is the ipv6 address routable?
# # if not we can not use this address (interface is not configured properly)
# if ! checkConn "$INTERNAL_IP6_ADDR"; then
# printerr "IPV6 enabled but address [$INTERNAL_IP6_ADDR] is not routable"
# exit 1
# fi
# export IPV6_ENABLED=1
# else
# export IPV6_ENABLED=0
# fi
# the address we put in the contact when registering to carriers via uac module
# by default it is set to the external IP of this server
export UAC_REG_ADDR="$EXTERNAL_IP_ADDR"
export INTERNAL_FQDN=$(getInternalFQDN)
export EXTERNAL_FQDN=$(getExternalFQDN)
if [[ -z "$EXTERNAL_FQDN" ]] || ! checkConn "$EXTERNAL_FQDN"; then
# if external fqdn is not routable set it to the internal fqdn instead
export EXTERNAL_FQDN="$INTERNAL_FQDN"
fi
else
printerr 'Network Mode is invalid, can not proceed any further'
exit 1
fi
# if the public ip address is not the same as the internal address then enable serverside NAT
if [[ "$EXTERNAL_IP_ADDR" != "$INTERNAL_IP_ADDR" ]]; then
export SERVERNAT=1
else
export SERVERNAT=0
fi
# same as above but for ipv6, note that NAT is rarely used on ipv6 networks
if (( ${IPV6_ENABLED} == 1 )) && [[ "$EXTERNAL_IP6_ADDR" != "$INTERNAL_IP6_ADDR" ]]; then
export SERVERNAT6=1
else
export SERVERNAT6=0
fi
# grab root db settings from env or settings file
export ROOT_DB_USER=${ROOT_DB_USER:-$(getConfigAttrib 'ROOT_DB_USER' ${DSIP_CONFIG_FILE})}
export ROOT_DB_PASS=${ROOT_DB_PASS:-$(decryptConfigAttrib 'ROOT_DB_PASS' ${DSIP_CONFIG_FILE})}
export ROOT_DB_HOST=${ROOT_DB_HOST:-$(getConfigAttrib 'ROOT_DB_HOST' ${DSIP_CONFIG_FILE})}
export ROOT_DB_PORT=${ROOT_DB_PORT:-$(getConfigAttrib 'ROOT_DB_PORT' ${DSIP_CONFIG_FILE})}
export ROOT_DB_NAME=${ROOT_DB_NAME:-$(getConfigAttrib 'ROOT_DB_NAME' ${DSIP_CONFIG_FILE})}
# grab kam db settings from env or settings file
export KAM_DB_HOST=${KAM_DB_HOST:-$(getConfigAttrib 'KAM_DB_HOST' ${DSIP_CONFIG_FILE})}
export KAM_DB_TYPE=${KAM_DB_TYPE:-$(getConfigAttrib 'KAM_DB_TYPE' ${DSIP_CONFIG_FILE})}
export KAM_DB_PORT=${KAM_DB_PORT:-$(getConfigAttrib 'KAM_DB_PORT' ${DSIP_CONFIG_FILE})}
export KAM_DB_NAME=${KAM_DB_NAME:-$(getConfigAttrib 'KAM_DB_NAME' ${DSIP_CONFIG_FILE})}
export KAM_DB_USER=${KAM_DB_USER:-$(getConfigAttrib 'KAM_DB_USER' ${DSIP_CONFIG_FILE})}
export KAM_DB_PASS=${KAM_DB_PASS:-$(decryptConfigAttrib 'KAM_DB_PASS' ${DSIP_CONFIG_FILE} 2>/dev/null)}
# set the email used to obtain LetsEncrypt Certificates
export DSIP_SSL_EMAIL="admin@${EXTERNAL_FQDN}"
export DSIP_ID=$(getConfigAttrib 'DSIP_ID' ${DSIP_CONFIG_FILE})
if [[ "$DSIP_ID" == "None" || -z "$DSIP_ID" ]]; then
export DSIP_ID=$(cat /etc/machine-id | hashCreds)
fi
export HOMER_ID=$(getConfigAttrib 'HOMER_ID' ${DSIP_CONFIG_FILE})
if [[ "$HOMER_ID" == "None" ]] || [[ -z "$HOMER_ID" ]]; then
export HOMER_ID=$(cat /etc/machine-id | hashCreds -l 4 | dd if=/dev/stdin of=/dev/stdout bs=1 count=8 2>/dev/null | hextoint)
fi
# find the repo where we are getting upgrades from
# note that remote is assumed to be "origin"
# note that the VCS is assumed to be git
GIT_REPO_URL=$(getConfigAttrib 'GIT_REPO_URL' ${DSIP_CONFIG_FILE})
GIT_RELEASE_URL=$(getConfigAttrib 'GIT_RELEASE_URL' ${DSIP_CONFIG_FILE})
export CURR_BACKUP_DIR=${CURR_BACKUP_DIR:-"${BACKUPS_DIR}/$(date '+%s')"}
}
# Check if we are on a VPS Cloud Instance
function setCloudPlatform() {
# 0 == not enabled, 1 == enabled
export AWS_ENABLED=0
export DO_ENABLED=0
export GCE_ENABLED=0
export AZURE_ENABLED=0
export VULTR_ENABLED=0
# -- amazon web service check --
if isInstanceAMI; then
export AWS_ENABLED=1
CLOUD_PLATFORM='AWS'
# -- digital ocean check --
elif isInstanceDO; then
export DO_ENABLED=1
CLOUD_PLATFORM='DO'
# -- google compute engine check --
elif isInstanceGCE; then
export GCE_ENABLED=1
CLOUD_PLATFORM='GCE'
# -- microsoft azure check --
elif isInstanceAZURE; then
export AZURE_ENABLED=1
CLOUD_PLATFORM='AZURE'
# -- vultr cloud check --
elif isInstanceVULTR; then
export VULTR_ENABLED=1
CLOUD_PLATFORM='VULTR'
# -- bare metal or unsupported cloud platform --
else
CLOUD_PLATFORM=''
fi
}
function displayLogo() {
echo "CiAgICAgXyAgX19fX18gX19fX18gX19fX18gIF9fX19fICAgICAgICAgICAgIF8gCiAgICB8IHwv
IF9fX198XyAgIF98ICBfXyBcfCAgX18gXCAgICAgICAgICAgfCB8ICAgICAgICAgICAKICBfX3wg
fCAoX19fICAgfCB8IHwgfF9fKSB8IHxfXykgfF9fXyAgXyAgIF98IHxfIF9fXyBfIF9fIAogLyBf
YCB8XF9fXyBcICB8IHwgfCAgX19fL3wgIF8gIC8vIF8gXHwgfCB8IHwgX18vIF8gXCAnX198Cnwg
KF98IHxfX19fKSB8X3wgfF98IHwgICAgfCB8IFwgXCAoXykgfCB8X3wgfCB8fCAgX18vIHwgICAK
IFxfXyxffF9fX19fL3xfX19fX3xffCAgICB8X3wgIFxfXF9fXy8gXF9fLF98XF9fXF9fX3xffCAg
IAoKQnVpbHQgaW4gRGV0cm9pdCwgVVNBIC0gUG93ZXJlZCBieSBLYW1haWxpbyAgICAgICAgICAg
ICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgICAKICAgClN1cHBv
cnQgY2FuIGJlIHB1cmNoYXNlZCBmcm9tIGh0dHBzOi8vZHNpcHJvdXRlci5vcmcvIAoKVGhhbmtz
IHRvIG91ciBzcG9uc29yOiBkT3BlblNvdXJjZSAoaHR0cHM6Ly9kb3BlbnNvdXJjZS5jb20pCg==" \
| base64 -d \
| { echo -e "\e[1;49;36m"; cat; echo -e "\e[39;49;00m"; }
}
# check if running as root
function validateRootPriv() {
if (( $(id -u 2>/dev/null) != 0 )); then
printerr "$0 must be run as root user"
exit 1
fi
}
# Validate OS and export OS specific config variables
function validateOSInfo() {
export DISTRO=$(getDistroName)
export DISTRO_VER=$(getDistroVer)
export DISTRO_MAJOR_VER=$(cut -d '.' -f 1 <<<"$DISTRO_VER")
export DISTRO_MINOR_VER=$(cut -s -d '.' -f 2 <<<"$DISTRO_VER")
if [[ "$DISTRO" == "debian" ]]; then
case "$DISTRO_VER" in
12)
KAM_VERSION=${KAM_VERSION:-58}
RTPENGINE_VER=${RTPENGINE_VER:-"mr11.5.1.11"}
export APT_STRETCH_PRIORITY=50 APT_BUSTER_PRIORITY=50 APT_BULLSEYE_PRIORITY=500 APT_BOOKWORM_PRIORITY=990
;;
11)
KAM_VERSION=${KAM_VERSION:-58}
RTPENGINE_VER=${RTPENGINE_VER:-"mr11.5.1.11"}
export APT_STRETCH_PRIORITY=50 APT_BUSTER_PRIORITY=50 APT_BULLSEYE_PRIORITY=990 APT_BOOKWORM_PRIORITY=500
;;
10)
KAM_VERSION=${KAM_VERSION:-58}
RTPENGINE_VER=${RTPENGINE_VER:-"mr11.5.1.11"}
export APT_STRETCH_PRIORITY=50 APT_BUSTER_PRIORITY=990 APT_BULLSEYE_PRIORITY=500 APT_BOOKWORM_PRIORITY=100
;;
9)
printerr "Your Operating System Version is DEPRECATED. To ask for support open an issue https://github.com/dOpensource/dsiprouter/"
KAM_VERSION=${KAM_VERSION:-55}
RTPENGINE_VER=${RTPENGINE_VER:-"mr9.5.5.1"}
;;
*)
printerr "Your Operating System Version is not supported yet. Please open an issue at https://github.com/dOpensource/dsiprouter/"
exit 1
;;
esac
elif [[ "$DISTRO" == "centos" ]]; then
case "$DISTRO_VER" in
8|9)
KAM_VERSION=${KAM_VERSION:-58}
RTPENGINE_VER=${RTPENGINE_VER:-"mr11.5.1.11"}
;;
7)
KAM_VERSION=${KAM_VERSION:-57}
RTPENGINE_VER=${RTPENGINE_VER:-"mr11.5.1.11"}
;;
*)
printerr "Your Operating System Version is not supported yet. Please open an issue at https://github.com/dOpensource/dsiprouter/"
exit 1
;;
esac
elif [[ "$DISTRO" == "amzn" ]]; then
case "$DISTRO_VER" in
2)
KAM_VERSION=${KAM_VERSION:-57}
RTPENGINE_VER=${RTPENGINE_VER:-"mr9.5.5.1"}
;;
*)
printerr "Your Operating System Version is not supported yet. Please open an issue at https://github.com/dOpensource/dsiprouter/"
exit 1
;;
esac
elif [[ "$DISTRO" == "ubuntu" ]]; then
case "$DISTRO_VER" in
22.04)
printwarn "Your operating System Version is in ALPHA support. Some features may not work yet. Use at your own risk."
KAM_VERSION=${KAM_VERSION:-58}
RTPENGINE_VER=${RTPENGINE_VER:-"mr9.5.5.1"}
export APT_FOCAL_PRIORITY=100 APT_JAMMY_PRIORITY=990
;;
20.04)
printwarn "Your Operating System Version is DEPRECATED. To ask for support open an issue https://github.com/dOpensource/dsiprouter/"
KAM_VERSION=${KAM_VERSION:-58}
RTPENGINE_VER=${RTPENGINE_VER:-"mr9.5.5.1"}
;;
*)
printerr "Your Operating System Version is not supported yet. Please open an issue at https://github.com/dOpensource/dsiprouter/"
exit 1
;;
esac
elif [[ "$DISTRO" =~ rhel|almalinux|rocky ]]; then
case "$DISTRO_MAJOR_VER" in
8)
printwarn "Your operating System Version is in ALPHA support. Some features may not work yet. Use at your own risk."
KAM_VERSION=${KAM_VERSION:-58}
RTPENGINE_VER=${RTPENGINE_VER:-"mr9.5.5.1"}
;;
*)
printerr "Your Operating System Version is not supported yet. Please open an issue at https://github.com/dOpensource/dsiprouter/"
exit 1
;;
esac
else
printerr "Your Operating System is not supported yet. Please open an issue at https://github.com/dOpensource/dsiprouter/"
exit 1
fi
# export it for external scripts
export KAM_VERSION
export RTPENGINE_VER
}
# run prior to any cmd being processed
function initialChecks() {
validateRootPriv
validateOSInfo
setStaticScriptSettings
setupScriptRequiredFiles
installScriptRequirements
setDynamicScriptSettings
}
# exported because its used throughout called scripts as well
function reconfigureMysqlSystemdService() {
local KAMDB_HOST="${SET_KAM_DB_HOST:-$KAM_DB_HOST}"
local KAMDB_LOCATION="$(cat ${DSIP_SYSTEM_CONFIG_DIR}/.mysqldblocation 2>/dev/null)"
case "$KAMDB_HOST" in
# in this case mysql server is running on this node
"localhost"|"127.0.0.1"|"::1"|"${INTERNAL_IP_ADDR}"|"${EXTERNAL_IP_ADDR}"|"${INTERNAL_IP6_ADDR}"|"${EXTERNAL_IP6_ADDR}"|"$(hostname 2>/dev/null)"|"$(hostname -f 2>/dev/null)")
# if previously was remote and now local re-generate service files
if [[ "${KAMDB_LOCATION}" == "remote" ]]; then
systemctl disable mariadb
rm -f /etc/systemd/system/mariadb.service 2>/dev/null
fi
printf '%s' 'local' > ${DSIP_SYSTEM_CONFIG_DIR}/.mysqldblocation
;;
# in this case mysql server is running on a remote node
*)
# if previously was local and now remote or inital run and is remote replace service files w/ dummy
if [[ "${KAMDB_LOCATION}" == "local" ]] || [[ "${KAMDB_LOCATION}" == "" ]]; then
systemctl disable mariadb
cp -f ${DSIP_PROJECT_DIR}/mysql/systemd/dummy.service /etc/systemd/system/mariadb.service
chmod 644 /etc/systemd/system/mariadb.service
fi
printf '%s' 'remote' > ${DSIP_SYSTEM_CONFIG_DIR}/.mysqldblocation
;;
esac
systemctl daemon-reload
systemctl enable mariadb
}
export -f reconfigureMysqlSystemdService
function generateDsiprouterConfig() {
mkdir -p ${BACKUPS_DIR}/gui/
cp -f ${DSIP_SYSTEM_CONFIG_DIR}/gui/*.py ${BACKUPS_DIR}/gui/ 2>/dev/null
rm -f ${DSIP_SYSTEM_CONFIG_DIR}/gui/*.py 2>/dev/null
cp -f ${DSIP_PROJECT_DIR}/gui/settings.py ${DSIP_CONFIG_FILE}
}
# TODO: update DB settings here as well, currently they are updated in dsiprouter.py
# ^^ this is required to support loading settings from DB, i.e. LOAD_SETTINGS_FROM='db'
function updateDsiprouterConfig() {
local NETWORK_MODE=${NETWORK_MODE:-$(getConfigAttrib 'NETWORK_MODE' ${DSIP_CONFIG_FILE})}
# the following variables are always updated
setConfigAttrib 'KAM_KAMCMD_PATH' "$(type -p kamcmd)" ${DSIP_CONFIG_FILE} -q
setConfigAttrib 'KAM_CFG_PATH' "$SYSTEM_KAMAILIO_CONFIG_FILE" ${DSIP_CONFIG_FILE} -q
setConfigAttrib 'KAM_TLSCFG_PATH' "$SYSTEM_KAMAILIO_TLS_CONFIG_FILE" ${DSIP_CONFIG_FILE} -q
setConfigAttrib 'RTP_CFG_PATH' "$SYSTEM_RTPENGINE_CONFIG_FILE" ${DSIP_CONFIG_FILE} -q
setConfigAttrib 'FLT_CARRIER' "$FLT_CARRIER" ${DSIP_CONFIG_FILE}
setConfigAttrib 'FLT_PBX' "$FLT_PBX" ${DSIP_CONFIG_FILE}
setConfigAttrib 'FLT_MSTEAMS' "$FLT_MSTEAMS" ${DSIP_CONFIG_FILE}
setConfigAttrib 'FLT_OUTBOUND' "$FLT_OUTBOUND" ${DSIP_CONFIG_FILE}
setConfigAttrib 'FLT_INBOUND' "$FLT_INBOUND" ${DSIP_CONFIG_FILE}
setConfigAttrib 'FLT_LCR_MIN' "$FLT_LCR_MIN" ${DSIP_CONFIG_FILE}
setConfigAttrib 'FLT_FWD_MIN' "$FLT_FWD_MIN" ${DSIP_CONFIG_FILE}
setConfigAttrib 'DSIP_PROJECT_DIR' "$DSIP_PROJECT_DIR" ${DSIP_CONFIG_FILE} -q
setConfigAttrib 'DSIP_DOCS_DIR' "$DSIP_DOCS_DIR" ${DSIP_CONFIG_FILE} -q
# the following variables are only updated when set
[[ -n "$DSIP_ID" ]] && setConfigAttrib 'DSIP_ID' "$DSIP_ID" ${DSIP_CONFIG_FILE} -qb
[[ -n "$DSIP_CLUSTER_ID" ]] && setConfigAttrib 'DSIP_CLUSTER_ID' "$DSIP_CLUSTER_ID" ${DSIP_CONFIG_FILE}
if [[ -n "$DSIP_CLUSTER_SYNC" ]]; then
if (( $DSIP_CLUSTER_SYNC == 1 )); then
setConfigAttrib 'DSIP_CLUSTER_SYNC' 'True' ${DSIP_CONFIG_FILE}
else
setConfigAttrib 'DSIP_CLUSTER_SYNC' 'False' ${DSIP_CONFIG_FILE}
fi
fi
[[ -n "$DSIP_PROTO" ]] && setConfigAttrib 'DSIP_PROTO' "$DSIP_PROTO" ${DSIP_CONFIG_FILE} -q
[[ -n "$DSIP_PORT" ]] && setConfigAttrib 'DSIP_PORT' "$DSIP_PORT" ${DSIP_CONFIG_FILE} -q
[[ -n "$DSIP_API_PROTO" ]] && setConfigAttrib 'DSIP_API_PROTO' "$DSIP_API_PROTO" ${DSIP_CONFIG_FILE} -q
[[ -n "$DSIP_API_PORT" ]] && setConfigAttrib 'DSIP_API_PORT' "$DSIP_API_PORT" ${DSIP_CONFIG_FILE}
[[ -n "$DSIP_PRIV_KEY" ]] && setConfigAttrib 'DSIP_PRIV_KEY' "$DSIP_PRIV_KEY" ${DSIP_CONFIG_FILE} -q
[[ -n "$DSIP_PID_FILE" ]] && setConfigAttrib 'DSIP_PID_FILE' "$DSIP_PID_FILE" ${DSIP_CONFIG_FILE} -q
[[ -n "$DSIP_UNIX_SOCK" ]] && setConfigAttrib 'DSIP_UNIX_SOCK' "$DSIP_UNIX_SOCK" ${DSIP_CONFIG_FILE} -q
[[ -n "$DSIP_IPC_SOCK" ]] && setConfigAttrib 'DSIP_IPC_SOCK' "$DSIP_IPC_SOCK" ${DSIP_CONFIG_FILE} -q
[[ -n "$DSIP_LOG_LEVEL" ]] && setConfigAttrib 'DSIP_LOG_LEVEL' "$DSIP_LOG_LEVEL" ${DSIP_CONFIG_FILE}
[[ -n "$DSIP_LOG_FACILITY" ]] && setConfigAttrib 'DSIP_LOG_FACILITY' "$DSIP_LOG_FACILITY" ${DSIP_CONFIG_FILE}
[[ -n "$DSIP_SSL_KEY" ]] && setConfigAttrib 'DSIP_SSL_KEY' "$DSIP_SSL_KEY" ${DSIP_CONFIG_FILE} -q
[[ -n "$DSIP_SSL_CERT" ]] && setConfigAttrib 'DSIP_SSL_CERT' "$DSIP_SSL_CERT" ${DSIP_CONFIG_FILE} -q
[[ -n "$DSIP_SSL_CA" ]] && setConfigAttrib 'DSIP_SSL_CA' "$DSIP_SSL_CA" ${DSIP_CONFIG_FILE} -q
[[ -n "$DSIP_SSL_EMAIL" ]] && setConfigAttrib 'DSIP_SSL_EMAIL' "$DSIP_SSL_EMAIL" ${DSIP_CONFIG_FILE} -q
[[ -n "$DSIP_CERTS_DIR" ]] && setConfigAttrib 'DSIP_CERTS_DIR' "$DSIP_CERTS_DIR" ${DSIP_CONFIG_FILE} -q
[[ -n "$VERSION" ]] && setConfigAttrib 'VERSION' "$VERSION" ${DSIP_CONFIG_FILE} -q
[[ -n "$ROLE" ]] && setConfigAttrib 'ROLE' "$ROLE" ${DSIP_CONFIG_FILE} -q
[[ -n "$GUI_INACTIVE_TIMEOUT" ]] && setConfigAttrib 'GUI_INACTIVE_TIMEOUT' "$GUI_INACTIVE_TIMEOUT" ${DSIP_CONFIG_FILE}
[[ -n "$KAM_DB_DRIVER" ]] && setConfigAttrib 'KAM_DB_DRIVER' "$KAM_DB_DRIVER" ${DSIP_CONFIG_FILE} -q
[[ -n "$KAM_DB_TYPE" ]] && setConfigAttrib 'KAM_DB_TYPE' "$KAM_DB_TYPE" ${DSIP_CONFIG_FILE} -q
[[ -n "$DEFAULT_AUTH_DOMAIN" ]] && setConfigAttrib 'DEFAULT_AUTH_DOMAIN' "$DEFAULT_AUTH_DOMAIN" ${DSIP_CONFIG_FILE} -q
[[ -n "$TELEBLOCK_GW_ENABLED" ]] && setConfigAttrib 'TELEBLOCK_GW_ENABLED' "$TELEBLOCK_GW_ENABLED" ${DSIP_CONFIG_FILE}
[[ -n "$TELEBLOCK_GW_IP" ]] && setConfigAttrib 'TELEBLOCK_GW_IP' "$TELEBLOCK_GW_IP" ${DSIP_CONFIG_FILE} -q
[[ -n "$TELEBLOCK_GW_PORT" ]] && setConfigAttrib 'TELEBLOCK_GW_PORT' "$TELEBLOCK_GW_PORT" ${DSIP_CONFIG_FILE} -q
[[ -n "$TELEBLOCK_MEDIA_IP" ]] && setConfigAttrib 'TELEBLOCK_MEDIA_IP' "$TELEBLOCK_MEDIA_IP" ${DSIP_CONFIG_FILE} -q
[[ -n "$TELEBLOCK_MEDIA_PORT" ]] && setConfigAttrib 'TELEBLOCK_MEDIA_PORT' "$TELEBLOCK_MEDIA_PORT" ${DSIP_CONFIG_FILE} -q
[[ -n "$FLOWROUTE_ACCESS_KEY" ]] && setConfigAttrib 'FLOWROUTE_ACCESS_KEY' "$FLOWROUTE_ACCESS_KEY" ${DSIP_CONFIG_FILE} -q
[[ -n "$FLOWROUTE_SECRET_KEY" ]] && setConfigAttrib 'FLOWROUTE_SECRET_KEY' "$FLOWROUTE_SECRET_KEY" ${DSIP_CONFIG_FILE} -q
[[ -n "$FLOWROUTE_API_ROOT_URL" ]] && setConfigAttrib 'FLOWROUTE_API_ROOT_URL' "$FLOWROUTE_API_ROOT_URL" ${DSIP_CONFIG_FILE} -q
[[ -n "$HOMER_ID" ]] && setConfigAttrib 'HOMER_ID' "$HOMER_ID" ${DSIP_CONFIG_FILE}
[[ -n "$HOMER_HEP_HOST" ]] && setConfigAttrib 'HOMER_HEP_HOST' "$HOMER_HEP_HOST" ${DSIP_CONFIG_FILE} -q
[[ -n "$HOMER_HEP_PORT" ]] && setConfigAttrib 'HOMER_HEP_PORT' "$HOMER_HEP_PORT" ${DSIP_CONFIG_FILE}
[[ -n "$UPLOAD_FOLDER" ]] && setConfigAttrib 'UPLOAD_FOLDER' "$UPLOAD_FOLDER" ${DSIP_CONFIG_FILE} -q
[[ -n "$MAIL_SERVER" ]] && setConfigAttrib 'MAIL_SERVER' "$MAIL_SERVER" ${DSIP_CONFIG_FILE} -q
[[ -n "$MAIL_PORT" ]] && setConfigAttrib 'MAIL_PORT' "$MAIL_PORT" ${DSIP_CONFIG_FILE}
if [[ -n "$MAIL_USE_TLS" ]]; then
if (( $MAIL_USE_TLS == 0 )); then
setConfigAttrib 'MAIL_USE_TLS' "False" ${DSIP_CONFIG_FILE}
else
setConfigAttrib 'MAIL_USE_TLS' "True" ${DSIP_CONFIG_FILE}
fi
fi
if [[ -n "$MAIL_ASCII_ATTACHMENTS" ]]; then
if (( $MAIL_ASCII_ATTACHMENTS == 1 )); then
setConfigAttrib 'MAIL_ASCII_ATTACHMENTS' "True" ${DSIP_CONFIG_FILE}
else
setConfigAttrib 'MAIL_ASCII_ATTACHMENTS' "False" ${DSIP_CONFIG_FILE}
fi
fi
[[ -n "$MAIL_USERNAME" ]] && setConfigAttrib 'MAIL_DEFAULT_SENDER' "dSIPRouter $EXTERNAL_FQDN <$MAIL_USERNAME>" ${DSIP_CONFIG_FILE} -q
[[ -n "$MAIL_DEFAULT_SUBJECT" ]] && setConfigAttrib 'MAIL_DEFAULT_SUBJECT' "$MAIL_DEFAULT_SUBJECT" ${DSIP_CONFIG_FILE} -q
[[ -n "$CLOUD_PLATFORM" ]] && setConfigAttrib 'CLOUD_PLATFORM' "$CLOUD_PLATFORM" ${DSIP_CONFIG_FILE} -q
[[ -n "$BACKUPS_DIR" ]] && setConfigAttrib 'BACKUP_FOLDER' "$BACKUPS_DIR" ${DSIP_CONFIG_FILE} -q
[[ -n "$DID_PREFIX_ALLOWED_CHARS" ]] && setConfigAttrib 'DID_PREFIX_ALLOWED_CHARS' "$DID_PREFIX_ALLOWED_CHARS" ${DSIP_CONFIG_FILE}
[[ -n "$LOAD_SETTINGS_FROM" ]] && setConfigAttrib 'LOAD_SETTINGS_FROM' "$LOAD_SETTINGS_FROM" ${DSIP_CONFIG_FILE} -q
# update settings based on values set by setDynamicScriptSettings()
setConfigAttrib 'NETWORK_MODE' "$NETWORK_MODE" ${DSIP_CONFIG_FILE}
if (( $IPV6_ENABLED == 1 )); then
setConfigAttrib 'IPV6_ENABLED' "True" ${DSIP_CONFIG_FILE}
else
setConfigAttrib 'IPV6_ENABLED' "False" ${DSIP_CONFIG_FILE}
fi
setConfigAttrib 'INTERNAL_IP_ADDR' "$INTERNAL_IP_ADDR" ${DSIP_CONFIG_FILE} -q
setConfigAttrib 'INTERNAL_IP_NET' "$INTERNAL_IP_NET" ${DSIP_CONFIG_FILE} -q
setConfigAttrib 'INTERNAL_IP6_ADDR' "$INTERNAL_IP6_ADDR" ${DSIP_CONFIG_FILE} -q
setConfigAttrib 'INTERNAL_IP6_NET' "$INTERNAL_IP6_NET" ${DSIP_CONFIG_FILE} -q
setConfigAttrib 'INTERNAL_FQDN' "$INTERNAL_FQDN" ${DSIP_CONFIG_FILE} -q
setConfigAttrib 'EXTERNAL_IP_ADDR' "$EXTERNAL_IP_ADDR" ${DSIP_CONFIG_FILE} -q
setConfigAttrib 'EXTERNAL_IP6_ADDR' "$EXTERNAL_IP6_ADDR" ${DSIP_CONFIG_FILE} -q
setConfigAttrib 'EXTERNAL_FQDN' "$EXTERNAL_FQDN" ${DSIP_CONFIG_FILE} -q
setConfigAttrib 'PUBLIC_IFACE' "$PUBLIC_IFACE" ${DSIP_CONFIG_FILE} -q
setConfigAttrib 'PRIVATE_IFACE' "$PRIVATE_IFACE" ${DSIP_CONFIG_FILE} -q
setConfigAttrib 'UAC_REG_ADDR' "$UAC_REG_ADDR" ${DSIP_CONFIG_FILE} -q
setConfigAttrib 'GIT_REPO_URL' "$GIT_REPO_URL" ${DSIP_CONFIG_FILE} -q
setConfigAttrib 'GIT_RELEASE_URL' "$GIT_RELEASE_URL" ${DSIP_CONFIG_FILE} -q
# TODO: the following are updated in setCredentials() and the config file should only be updated here
# i.e. settings the variables elsewhere is fine but any changes to the config file or DB should be centralised here
# DSIP_GUI_USER
# DSIP_GUI_PASS
# DSIP_API_TOKEN
# DSIP_MAIL_USER
# DSIP_MAIL_PASS
# DSIP_IPC_PASS
# KAM_DB_USER
# KAM_DB_PASS
# KAM_DB_HOST
# KAM_DB_PORT
# KAM_DB_NAME
# ROOT_DB_HOST
# ROOT_DB_PORT
# ROOT_DB_USER
# ROOT_DB_PASS
# ROOT_DB_NAME
# DSIP_SESSION_KEY
# TODO: the following settings are only updatable via the GUI
# TRANSNEXUS_AUTHSERVICE_ENABLED
# TRANSNEXUS_AUTHSERVICE_HOST
# TRANSNEXUS_LICENSE_KEY
# TRANSNEXUS_VERIFYSERVICE_ENABLED
# TRANSNEXUS_VERIFYSERVICE_HOST
# STIR_SHAKEN_ENABLED
# STIR_SHAKEN_PREFIX_A
# STIR_SHAKEN_PREFIX_B
# STIR_SHAKEN_PREFIX_C
# STIR_SHAKEN_PREFIX_INVALID
# STIR_SHAKEN_BLOCK_INVALID
# STIR_SHAKEN_CERT_URL
# STIR_SHAKEN_KEY_PATH
# MSTEAMS_DNS_ENDPOINTS
# MSTEAMS_IP_ENDPOINTS
# TODO: workaround to update DB settings until next major release (v0.80)
if [[ "$LOAD_SETTINGS_FROM" == "db" ]]; then
setConfigAttrib 'LOAD_SETTINGS_FROM' 'file' ${DSIP_CONFIG_FILE} -q
${PYTHON_CMD} -c "import os,sys; os.chdir('${DSIP_PROJECT_DIR}/gui'); sys.path.insert(0, '${DSIP_SYSTEM_CONFIG_DIR}/gui'); from dsiprouter import syncSettings; syncSettings();"
setConfigAttrib 'LOAD_SETTINGS_FROM' 'db' ${DSIP_CONFIG_FILE} -q
fi
return 0
}
# TODO: these variables should be ephemeral, set as environment variables when running the service, no need to store them
function updateDsiprouterConfigRuntimeSettings() {
if (( ${DEBUG} == 1 )); then
setConfigAttrib 'DEBUG' 'True' ${DSIP_CONFIG_FILE}
else
setConfigAttrib 'DEBUG' 'False' ${DSIP_CONFIG_FILE}
fi
}
function updateDsiprouterStartup {
local KAM_UPDATE_OPTS=""
# update dsiprouter configs on reboot
removeInitCmd "/usr/bin/dsiprouter updatedsipconfig"
addInitCmd "/usr/bin/dsiprouter updatedsipconfig $KAM_UPDATE_OPTS"
# make sure dsip-init service runs prior to dsiprouter service
removeDependsOnInit "dsiprouter.service"
addDependsOnInit "dsiprouter.service"
}
# supported methods for renewing certificates:
# 1. using Let's Encrypt / certbot
# 2. issuing a new self-signed cert
function renewSSLCert() {
local DEFAULT_CERT_UPLOADED CERT_ISSUER RENEW_START_TS LAST_CHANGE_TS
# Do not renew if the admin uploaded a default cert
DEFAULT_CERT_UPLOADED=$(
withKamDB mysql -sN -e "select count(*) from dsip_certificates where domain='default'" 2>/dev/null
)
if (( ${DEFAULT_CERT_UPLOADED:-0} == 1 )); then
printwarn "Current X509 certificate for dSIPRouter can not be automatically renewed"
return 1
fi
CERT_ISSUER=$(
openssl x509 -in ${DSIP_SSL_KEY} -noout -nameopt compat -issuer 2>/dev/null |
perl -pe 's%^.*?/O=([^/]*).*?$%\1%'
)
case "$CERT_ISSUER" in
"Let's Encrypt")
if certbot -n certificates | grep -q 'No certs found' &>/dev/null; then
printwarn "No LetsEncrypt certificates managed by Certbot found"
return 1
fi
RENEW_START_TS=$(date '+%s')
certbot -n renew
if (( $? == 0 )); then
# we only want to reload the live cert if it was actually changed
LAST_CHANGE_TS=$(stat -c '%Y' /etc/letsencrypt/live/${EXTERNAL_FQDN}/fullchain.pem)
if (( $? != 0 )); then
printerr "Could not find new certificate for ${EXTERNAL_FQDN}"
return 1
fi
if (( $LAST_CHANGE_TS < $RENEW_START_TS )); then
return 0
fi
rm -f ${DSIP_CERTS_DIR}/dsiprouter*
cp -f /etc/letsencrypt/live/${EXTERNAL_FQDN}/fullchain.pem ${DSIP_SSL_CERT}
cp -f /etc/letsencrypt/live/${EXTERNAL_FQDN}/privkey.pem ${DSIP_SSL_KEY}
else
printerr "Failed renewing certificate for ${EXTERNAL_FQDN} using LetsEncrypt"
return 1
fi
;;
dSIPRouter)
openssl req -new -newkey rsa:4096 -x509 -sha256 -days 365 -nodes \
-out ${DSIP_SSL_CERT} \
-keyout ${DSIP_SSL_KEY} \
-subj "/C=US/ST=MI/L=Detroit/O=dSIPRouter/CN=${EXTERNAL_FQDN}"
if (( $? != 0 )); then
printerr "Failed renewing self-signed certificate for ${EXTERNAL_FQDN}"
return 1
fi
;;
*)
printwarn "Current X509 certificate for dSIPRouter can not be automatically renewed"
return 1
;;
esac
updatePermissions -certs &&
kamcmd tls.reload &&
return 0 ||
return 1
}
function configureSSL() {
# Check if certificates already exists. If so, use them and exit
if [[ -f "${DSIP_SSL_CERT}" && -f "${DSIP_SSL_KEY}" ]]; then
printwarn "Using certificates found in ${DSIP_CERTS_DIR}"
updatePermissions -certs
return
fi
# Stop nginx if started so that LetsEncrypt can leverage port 80
if [[ -f "${DSIP_SYSTEM_CONFIG_DIR}/.dsiprouterinstalled" ]]; then
docker stop dsiprouter-nginx 2>/dev/null
else
firewall-cmd --zone=public --add-port=80/tcp
fi
# Override the hostname if -o or --override=<hostname> is provided
if [[ -n "${DNS_NAME_OVERRIDE}" ]]; then
EXTERNAL_FQDN=${DNS_NAME_OVERRIDE}
fi
# Try to create cert using LetsEncrypt's first
printdbg "Generating Certs for ${EXTERNAL_FQDN} using LetsEncrypt"
certbot certonly --standalone --non-interactive --agree-tos -d ${EXTERNAL_FQDN} -m ${DSIP_SSL_EMAIL} \
--server https://acme-v02.api.letsencrypt.org/directory --force-renewal --preferred-chain "ISRG Root X1"
if (( $? == 0 )); then
rm -f ${DSIP_CERTS_DIR}/dsiprouter*
cp -f /etc/letsencrypt/live/${EXTERNAL_FQDN}/fullchain.pem ${DSIP_SSL_CERT}
cp -f /etc/letsencrypt/live/${EXTERNAL_FQDN}/privkey.pem ${DSIP_SSL_KEY}
else
printwarn "Failed Generating Certs for ${EXTERNAL_FQDN} using LetsEncrypt"
# Worst case, generate a Self-Signed Certificate
printdbg "Generating dSIPRouter Self-Signed Certificates"
openssl req -new -newkey rsa:4096 -x509 -sha256 -days 365 -nodes -out ${DSIP_SSL_CERT} -keyout ${DSIP_SSL_KEY} -subj "/C=US/ST=MI/L=Detroit/O=dSIPRouter/CN=${EXTERNAL_FQDN}"
fi
# Add Nightly Cronjob to renew certs if not already there
if ! crontab -u root -l 2>/dev/null | grep -q '/usr/bin/dsiprouter renewsslcert' 2>/dev/null; then
cronAppend -u root '0 0 * * * /usr/bin/dsiprouter renewsslcert'
fi
updatePermissions -certs
# Start nginx if dSIP was installed
if [[ -f "${DSIP_SYSTEM_CONFIG_DIR}/.dsiprouterinstalled" ]]; then
docker stop dsiprouter-nginx 2>/dev/null
else
firewall-cmd --zone=public --remove-port=80/tcp
fi
}
# updates and settings in kam config that may change
# should be run after changing settings.py or change in network configurations
# TODO: support configuring separate asterisk realtime db conns / clusters (would need separate setting in settings.py)
function updateKamailioConfig() {
local DSIP_ID=${DSIP_ID:-$(getConfigAttrib 'DSIP_ID' ${DSIP_CONFIG_FILE})}
local DSIP_CLUSTER_ID=${DSIP_CLUSTER_ID:-$(getConfigAttrib 'DSIP_CLUSTER_ID' ${DSIP_CONFIG_FILE})}
local DSIP_CLUSTER_SYNC=${DSIP_CLUSTER_SYNC:-$([[ "$(getConfigAttrib 'DSIP_CLUSTER_SYNC' ${DSIP_CONFIG_FILE})" == "True" ]] && echo '1' || echo '0')}
local DSIP_VERSION=${DSIP_VERSION:-$(getConfigAttrib 'VERSION' ${DSIP_CONFIG_FILE})}
local HOMER_ID=${HOMER_ID:-$(getConfigAttrib 'HOMER_ID' ${DSIP_CONFIG_FILE})}
local DSIP_API_BASEURL="$(getConfigAttrib 'DSIP_API_PROTO' ${DSIP_CONFIG_FILE})://127.0.0.1:$(getConfigAttrib 'DSIP_API_PORT' ${DSIP_CONFIG_FILE})"
local DSIP_API_TOKEN=${DSIP_API_TOKEN:-$(decryptConfigAttrib 'DSIP_API_TOKEN' ${DSIP_CONFIG_FILE} 2>/dev/null)}
local DEBUG=${DEBUG:-$([[ "$(getConfigAttrib 'DEBUG' ${DSIP_CONFIG_FILE})" == "True" ]] && echo '1' || echo '0')}
local ROLE=${ROLE:-$(getConfigAttrib 'ROLE' ${DSIP_CONFIG_FILE})}
local TELEBLOCK_GW_ENABLED=${TELEBLOCK_GW_ENABLED:-$(getConfigAttrib 'TELEBLOCK_GW_ENABLED' ${DSIP_CONFIG_FILE})}
local TELEBLOCK_GW_IP=${TELEBLOCK_GW_IP:-$(getConfigAttrib 'TELEBLOCK_GW_IP' ${DSIP_CONFIG_FILE})}
local TELEBLOCK_GW_PORT=${TELEBLOCK_GW_PORT:-$(getConfigAttrib 'TELEBLOCK_GW_PORT' ${DSIP_CONFIG_FILE})}
local TELEBLOCK_MEDIA_IP=${TELEBLOCK_MEDIA_IP:-$(getConfigAttrib 'TELEBLOCK_MEDIA_IP' ${DSIP_CONFIG_FILE})}
local TELEBLOCK_MEDIA_PORT=${TELEBLOCK_MEDIA_PORT:-$(getConfigAttrib 'TELEBLOCK_MEDIA_PORT' ${DSIP_CONFIG_FILE})}
local KAM_WSS_PORT=${KAM_WSS_PORT:-$(getConfigAttrib 'KAM_WSS_PORT' ${DSIP_CONFIG_FILE})}
local KAM_SIP_PORT=${KAM_SIP_PORT:-$(getConfigAttrib 'KAM_SIP_PORT' ${DSIP_CONFIG_FILE})}
local KAM_SIPS_PORT=${KAM_SIPS_PORT:-$(getConfigAttrib 'KAM_SIPS_PORT' ${DSIP_CONFIG_FILE})}
local KAM_DMQ_PORT=${KAM_DMQ_PORT:-$(getConfigAttrib 'KAM_DMQ_PORT' ${DSIP_CONFIG_FILE})}
local HOMER_HEP_HOST=${HOMER_HEP_HOST:-$(getConfigAttrib 'HOMER_HEP_HOST' ${DSIP_CONFIG_FILE})}
local HOMER_HEP_PORT=${HOMER_HEP_PORT:-$(getConfigAttrib 'HOMER_HEP_PORT' ${DSIP_CONFIG_FILE})}
local NETWORK_MODE=${NETWORK_MODE:-$(getConfigAttrib 'NETWORK_MODE' ${DSIP_CONFIG_FILE})}
# update kamailio config file
if (( $DEBUG == 1 )); then
enableKamailioConfigAttrib 'WITH_DEBUG' ${DSIP_KAMAILIO_CONFIG_FILE}
else
disableKamailioConfigAttrib 'WITH_DEBUG' ${DSIP_KAMAILIO_CONFIG_FILE}
fi
if (( $SERVERNAT == 1 )); then
enableKamailioConfigAttrib 'WITH_SERVERNAT' ${DSIP_KAMAILIO_CONFIG_FILE}
else
disableKamailioConfigAttrib 'WITH_SERVERNAT' ${DSIP_KAMAILIO_CONFIG_FILE}
fi
if (( $SERVERNAT6 == 1 )); then
enableKamailioConfigAttrib 'WITH_SERVERNAT6' ${DSIP_KAMAILIO_CONFIG_FILE}
else
disableKamailioConfigAttrib 'WITH_SERVERNAT6' ${DSIP_KAMAILIO_CONFIG_FILE}
fi
if (( $IPV6_ENABLED == 1 )); then
enableKamailioConfigAttrib 'WITH_IPV6' ${DSIP_KAMAILIO_CONFIG_FILE}
else
disableKamailioConfigAttrib 'WITH_IPV6' ${DSIP_KAMAILIO_CONFIG_FILE}
fi
if (( $NETWORK_MODE == 2 )); then
enableKamailioConfigAttrib 'WITH_DMZ' ${DSIP_KAMAILIO_CONFIG_FILE}
else
disableKamailioConfigAttrib 'WITH_DMZ' ${DSIP_KAMAILIO_CONFIG_FILE}
fi
if (( $DSIP_CLUSTER_SYNC == 1 )); then
enableKamailioConfigAttrib 'WITH_DMQ' ${DSIP_KAMAILIO_CONFIG_FILE}
setKamailioConfigSubst 'DMQ_REPLICATE_ENABLED' '1' ${DSIP_KAMAILIO_CONFIG_FILE}
else
disableKamailioConfigAttrib 'WITH_DMQ' ${DSIP_KAMAILIO_CONFIG_FILE}
setKamailioConfigSubst 'DMQ_REPLICATE_ENABLED' '0' ${DSIP_KAMAILIO_CONFIG_FILE}
fi
if [[ -n "$HOMER_HEP_HOST" ]]; then
enableKamailioConfigAttrib 'WITH_HOMER' ${DSIP_KAMAILIO_CONFIG_FILE}
else
disableKamailioConfigAttrib 'WITH_HOMER' ${DSIP_KAMAILIO_CONFIG_FILE}
fi
if [[ -n "$DSIP_ID" && "$DSIP_ID" != "None" ]]; then
setKamailioConfigSubst 'DSIP_ID' "$DSIP_ID" ${DSIP_KAMAILIO_CONFIG_FILE}
fi
if [[ -n "$HOMER_ID" && "$HOMER_ID" != "None" ]]; then
setKamailioConfigSubst 'HOMER_ID' "$HOMER_ID" ${DSIP_KAMAILIO_CONFIG_FILE}
fi
if lsmod | awk '$1 == "sctp" {rc=1; exit;}; END {exit !rc;}'; then
enableKamailioConfigAttrib 'WITH_SCTP' ${DSIP_KAMAILIO_CONFIG_FILE}
else
disableKamailioConfigAttrib 'WITH_SCTP' ${DSIP_KAMAILIO_CONFIG_FILE}
fi
setKamailioConfigSubst 'DSIP_CLUSTER_ID' "${DSIP_CLUSTER_ID}" ${DSIP_KAMAILIO_CONFIG_FILE}
setKamailioConfigSubst 'DSIP_VERSION' "${DSIP_VERSION}" ${DSIP_KAMAILIO_CONFIG_FILE}
setKamailioConfigSubst 'INTERNAL_IP_ADDR' "${INTERNAL_IP_ADDR}" ${DSIP_KAMAILIO_CONFIG_FILE}
setKamailioConfigSubst 'INTERNAL_IP6_ADDR' "${INTERNAL_IP6_ADDR}" ${DSIP_KAMAILIO_CONFIG_FILE}
setKamailioConfigSubst 'INTERNAL_IP_NET' "${INTERNAL_IP_NET}" ${DSIP_KAMAILIO_CONFIG_FILE}
setKamailioConfigSubst 'INTERNAL_IP6_NET' "${INTERNAL_IP_NET6}" ${DSIP_KAMAILIO_CONFIG_FILE}
setKamailioConfigSubst 'EXTERNAL_IP_ADDR' "${EXTERNAL_IP_ADDR}" ${DSIP_KAMAILIO_CONFIG_FILE}
setKamailioConfigSubst 'EXTERNAL_IP6_ADDR' "${EXTERNAL_IP6_ADDR}" ${DSIP_KAMAILIO_CONFIG_FILE}
setKamailioConfigSubst 'INTERNAL_FQDN' "${INTERNAL_FQDN}" ${DSIP_KAMAILIO_CONFIG_FILE}
setKamailioConfigSubst 'EXTERNAL_FQDN' "${EXTERNAL_FQDN}" ${DSIP_KAMAILIO_CONFIG_FILE}
setKamailioConfigSubst 'UAC_REG_ADDR' "${UAC_REG_ADDR}" ${DSIP_KAMAILIO_CONFIG_FILE}
setKamailioConfigSubst 'WSS_PORT' "${KAM_WSS_PORT}" ${DSIP_KAMAILIO_CONFIG_FILE}
setKamailioConfigSubst 'SIP_PORT' "${KAM_SIP_PORT}" ${DSIP_KAMAILIO_CONFIG_FILE}
setKamailioConfigSubst 'SIPS_PORT' "${KAM_SIPS_PORT}" ${DSIP_KAMAILIO_CONFIG_FILE}
setKamailioConfigSubst 'DMQ_PORT' "${KAM_DMQ_PORT}" ${DSIP_KAMAILIO_CONFIG_FILE}
setKamailioConfigSubst 'HOMER_HOST' "${HOMER_HEP_HOST}" ${DSIP_KAMAILIO_CONFIG_FILE}
setKamailioConfigSubst 'HEP_PORT' "${HOMER_HEP_PORT}" ${DSIP_KAMAILIO_CONFIG_FILE}
setKamailioConfigGlobal 'server.api_server' "${DSIP_API_BASEURL}" ${DSIP_KAMAILIO_CONFIG_FILE}
setKamailioConfigGlobal 'server.api_token' "${DSIP_API_TOKEN}" ${DSIP_KAMAILIO_CONFIG_FILE}
setKamailioConfigGlobal 'server.role' "${ROLE}" ${DSIP_KAMAILIO_CONFIG_FILE}
setKamailioConfigGlobal 'teleblock.gw_enabled' "${TELEBLOCK_GW_ENABLED}" ${DSIP_KAMAILIO_CONFIG_FILE}
setKamailioConfigGlobal 'teleblock.gw_ip' "${TELEBLOCK_GW_IP}" ${DSIP_KAMAILIO_CONFIG_FILE}
setKamailioConfigGlobal 'teleblock.gw_port' "${TELEBLOCK_GW_PORT}" ${DSIP_KAMAILIO_CONFIG_FILE}
setKamailioConfigGlobal 'teleblock.media_ip' "${TELEBLOCK_MEDIA_IP}" ${DSIP_KAMAILIO_CONFIG_FILE}
setKamailioConfigGlobal 'teleblock.media_port' "${TELEBLOCK_MEDIA_PORT}" ${DSIP_KAMAILIO_CONFIG_FILE}
# hot reloading global settings
if systemctl is-active --quiet kamailio 2>/dev/null; then
sendKamCmd cfg.sets server role "${ROLE}" &>/dev/null
sendKamCmd cfg.sets server api_server "${DSIP_API_BASEURL}" &>/dev/null
sendKamCmd cfg.sets server api_token "${DSIP_API_TOKEN}" &>/dev/null
sendKamCmd cfg.seti teleblock gw_enabled "${TELEBLOCK_GW_ENABLED}" &>/dev/null
sendKamCmd cfg.sets teleblock gw_ip "${TELEBLOCK_GW_IP}" &>/dev/null
sendKamCmd cfg.seti teleblock gw_port "${TELEBLOCK_GW_PORT}" &>/dev/null
sendKamCmd cfg.sets teleblock media_ip "${TELEBLOCK_MEDIA_IP}" &>/dev/null
sendKamCmd cfg.seti teleblock media_port "${TELEBLOCK_MEDIA_PORT}" &>/dev/null
fi
# check for cluster db connection and set kam db config settings appropriately
# note: the '@' symbol must be escaped in perl regex
if printf '%s' "$KAM_DB_HOST" | grep -q -oP '(\[.*\]|.*,.*)'; then
# db connection is clustered
enableKamailioConfigAttrib 'WITH_DBCLUSTER' ${DSIP_KAMAILIO_CONFIG_FILE}
# TODO: support different type/user/pass/port/name per connection
# TODO: support multiple clusters
local KAM_DB_CLUSTER_CONNS=""
local KAM_DB_CLUSTER_MODES=""
local KAM_DB_CLUSTER_NODES=$(printf '%s' "$KAM_DB_HOST" | tr -d '[]'"'"'"' | tr ',' ' ')
local i=1
for NODE in $KAM_DB_CLUSTER_NODES; do
KAM_DB_CLUSTER_CONNS+="modparam('db_cluster', 'connection', 'c${i}=>${KAM_DB_TYPE}://${KAM_DB_USER}:${KAM_DB_PASS}\\@${NODE}:${KAM_DB_PORT}/${KAM_DB_NAME}')\n"
KAM_DB_CLUSTER_MODES+="c${i}=9r9r;"
i=$((i+1))
done
KAM_DB_CLUSTER_MODES="modparam('db_cluster', 'cluster', 'dbcluster=>${KAM_DB_CLUSTER_MODES}')"
perl -e "\$dbcluster='${KAM_DB_CLUSTER_CONNS}${KAM_DB_CLUSTER_MODES}';" \
-0777 -i -pe 's~(modparam\("db_cluster", "connection".*\s)+(modparam\("db_cluster", "cluster".*)~${dbcluster}~gm' ${DSIP_KAMAILIO_CONFIG_FILE}
else
local DBURL="${KAM_DB_TYPE}://${KAM_DB_USER}:${KAM_DB_PASS}@${KAM_DB_HOST}:${KAM_DB_PORT}/${KAM_DB_NAME}"
setKamailioConfigDburl "DBURL" "${DBURL}" ${DSIP_KAMAILIO_CONFIG_FILE}
setKamailioConfigDburl "SQLCONN_KAM" "kam=>${DBURL}" ${DSIP_KAMAILIO_CONFIG_FILE}
setKamailioConfigDburl "SQLCONN_AST" "asterisk=>${DBURL}" ${DSIP_KAMAILIO_CONFIG_FILE}
fi
# update kamailio TLS config file
# if (( ${IPV6_ENABLED} == 1 )); then
# perl -e "\$external_ip='${EXTERNAL_IP_ADDR}'; \$wss_port='${KAM_WSS_PORT}'; "'$ipv6_config=
# "[server:['"${EXTERNAL_IP6_ADDR}"']:'"${KAM_WSS_PORT}"']\n" .
# "method = TLSv1.2+\n" .
# "verify_certificate = no\n" .